CVE-2017-1000455

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
02/01/2018
Last modified:
30/01/2018

Description

GuixSD prior to Git commit 5e66574a128937e7f2fcf146d146225703ccfd5d used POSIX hard links incorrectly, leading the creation of setuid executables in "the store", violating a fundamental security assumption of GNU Guix.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:gnu:guixsd:*:*:*:*:*:*:*:* 0.13.0 (including)


References to Advisories, Solutions, and Tools